
aisecplus-week01-servicenow-ai-security-incident
Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS

Java-based tester for CVE-2022-21449 ECDSA signature verification vulnerability. Checks JVM for the Psychic Signatures bug and reports vulnerable or…

Public advisory landing page for CVE-2026-54519: missing ownership checks in ai-agent-automation memory APIs enabling cross-user memory read and…

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。

The code for personally reproducing the corresponding vulnerability

The code for personally reproducing the corresponding vulnerability

Educational lab demonstrating unauthenticated RCE in Langflow via CVE-2026-33017, with automated VM setup and a PoC exploit for reverse shell.

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

Exploit and test stand for CVE-2025-41115

Technical audit and reproduction of CVE-2026-21858, an n8n RCE chain exploiting Content-Type confusion for arbitrary file read, session forgery, and…

Functional proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a pre-authentication heap memory disclosure vulnerability in MongoDB. Includes…

Proof-of-Concept (PoC) for CVE-2025-62168 👾

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

CVE-2023-46988: ONLYOFFICE Path Traversal Exploit